Investigation reveals illicit online marketplace selling sensitive personal data including NID records and call logs in Bangladesh

A thriving underground digital marketplace has emerged, facilitating the illegal sale of sensitive personal data belonging to citizens. Investigations by the research organization Dismislab have uncovered a sophisticated network operating across Facebook, Telegram, WhatsApp, and dedicated websites where individuals can purchase National Identity (NID) cards, Call Detail Records (CDR), real-time mobile locations, SMS logs, Tax Identification Numbers (TIN), passport details, and mobile financial service statements.
Dismislab’s investigation identified 10 active websites dedicated to the trade of personal information. Furthermore, researchers documented more than 600 advertisements for such services on Facebook alone within a single month. The investigation was triggered in June when researchers discovered advertisements for voter list sales in the comments section of a Facebook post. Using the keyword “sign copy,” they uncovered 675 posts, 605 of which explicitly offered personal data for sale between June 15 and July 15.
To test the system, researchers engaged with a Telegram group titled “Voter List.” After providing a target mobile number and paying 500 taka, researchers received a PDF copy of the associated NID card within 17 minutes. The document contained accurate details, including the individual’s photograph, birth date, and even a recently updated entry of their mother’s name.
The scope of the illicit trade extends far beyond basic identity theft. Accounts operating under names such as “Help BD” offer comprehensive surveillance services, including birth and death registration records, IMEI numbers, police clearance certificates, and land development tax receipts. In one instance, researchers paid 1,050 taka to obtain three months of CDR data for a Grameenphone number. The file, delivered within two and a half hours, contained a precise log of recent contacts, call durations, and call types that matched the actual records of the subscriber. Another request for location tracking yielded the target’s recent activity, tower-based location, and a Google Maps link within 16 minutes.
The digital black market operates through a complex hierarchy. Many social media vendors act as middlemen, purchasing data from larger databases or external websites before reselling it for a profit. One vendor, who manages a website based in Chandpur, admitted to buying call history records for 800 taka and reselling them for 900 taka, while also offering mobile financial service statements for 4,500 taka. The vendor claimed that their primary source accesses government servers by exploiting API vulnerabilities, though this assertion remains unverified.
The data repository has been growing steadily since 2023, with advertisements for these services appearing even in YouTube content as recently as March 2025. Investigations revealed that at least 112 unique mobile numbers and 36 active Facebook groups are being utilized to coordinate these transactions.
Security experts have raised alarms over the severe implications of this data breach. Information technology specialist Suman Ahmed Sabir warned that access to CDRs and real-time location data allows third parties to reconstruct an individual’s movement patterns and social connections. Such exposure significantly elevates the risk of targeted surveillance, harassment, and sophisticated financial fraud.